CVE-2025-52645

HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modified model artifacts being used, potentially leading to integrity concerns or unintended behaviour.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:aion:*:*:*:*:*:*:*:*

History

18 Mar 2026, 20:38

Type Values Removed Values Added
First Time Hcltech aion
Hcltech
Summary
  • (es) HCL AION está afectado por una vulnerabilidad donde los mecanismos de empaquetado y distribución de modelos podrían no incluir suficiente verificación de autenticidad. Esto podría permitir la posibilidad de que se utilicen artefactos de modelo no verificados o modificados, lo que podría llevar a problemas de integridad o a un comportamiento no deseado.
CPE cpe:2.3:a:hcltech:aion:*:*:*:*:*:*:*:*
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129410 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129410 - Vendor Advisory

16 Mar 2026, 21:16

Type Values Removed Values Added
CWE CWE-345

16 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 15:16

Updated : 2026-03-18 20:38


NVD link : CVE-2025-52645

Mitre link : CVE-2025-52645

CVE.ORG link : CVE-2025-52645


JSON object : View

Products Affected

hcltech

  • aion
CWE
CWE-345

Insufficient Verification of Data Authenticity